Description
Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is an unauthenticated PHP Object Injection in ThemeREX Addons plugin versions older than 2.45.0. When an attacker supplies a specially crafted serialized payload that the plugin unserializes, arbitrary PHP code can be executed on the host, enabling a full compromise of the WordPress installation. Based on the description, it is inferred that the attacker could run any code on the server, potentially affecting confidentiality, integrity, and availability of the site.

Affected Systems

The Vulnerability impacts the ThemeREX ThemeREX Addons WordPress plugin. Any installation running a version prior to 2.45.0 is affected. ThemeREX distributes the plugin under the ThemeRex vendor name and the affected versions are all releases before the 2.45.0 update.

Risk and Exploitability

The CVSS score of 9.8 indicates Critical severity, and the EPSS score of less than 1% suggests that exploitation is currently rare. The flaw is unauthenticated, meaning it can be triggered without logging into the site. Based on the description, the likely attack vector is delivery of a crafted serialized payload through a publicly accessible HTTP request that triggers the plugin’s unserialize routine. The vulnerability is not listed in CISA KEV, and no public exploit evidence is available at the time of this analysis.

Generated by OpenCVE AI on September 21, 2026 at 04:50 UTC.

Remediation

Vendor Solution

Update the WordPress ThemeREX Addons Plugin to the latest available version (at least 2.45.0).


OpenCVE Recommended Actions

  • Update the ThemeREX Addons plugin to version 2.45.0 or later.
  • If the plugin is not required, uninstall or disable it entirely.
  • Apply a web application firewall rule that blocks requests containing malicious serialized objects or restrict the relevant plugin endpoints to trusted users only.

Generated by OpenCVE AI on September 21, 2026 at 04:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Themerex
Themerex themerex Addons
Wordpress
Wordpress wordpress
Vendors & Products Themerex
Themerex themerex Addons
Wordpress
Wordpress wordpress

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
Title WordPress ThemeREX Addons plugin < 2.45.0 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Themerex Themerex Addons
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-11T19:46:19.109Z

Reserved: 2026-07-13T06:15:10.221Z

Link: CVE-2026-62105

cve-icon Vulnrichment

Updated: 2026-09-11T19:46:15.589Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T19:17:43.337

Modified: 2026-09-11T21:17:02.457

Link: CVE-2026-62105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:00:14Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data